Privacy policy
Last updated: July 15, 2026
1. Who we are
Pigeon (“the application”, “we”) is an automation tool that, with the authorization of the owner of a professional Instagram account, detects comments containing a keyword and automatically sends a private reply (direct message) through Meta’s official API.
Data controller: Antonin Langlade. Contact: antonin.langlade@gmail.com.
2. Data we process
When a comment is posted on a post of a connected account, we receive and process the following information through the Meta API:
- the content of the comment;
- the username and Instagram id of its author;
- the id of the post concerned;
- the time it was received.
We collect no passwords, no payment data and no private content beyond what is strictly necessary for the operation described here.
3. Purposes
This data is used only to:
- detect the keyword configured by the account owner;
- send the private reply (ref / link) to the author of the comment;
- keep a technical log of what was processed, for reliability and debugging.
4. Legal basis
Processing relies on the account owner’s legitimate interest in replying to their community, and on the implicit consent of the person who comments publicly with the explicit aim of getting the reply announced by the post.
5. Hosting and security
Data is stored on Supabase (a PostgreSQL database) and the application is hosted on Vercel. Server access uses a confidential service key; no sensitive data is exposed on the client. Traffic goes over HTTPS and every incoming webhook is authenticated by signature (X-Hub-Signature-256).
6. Data sharing
We do not sell or rent your data. It is shared only with the technical subprocessors that are strictly necessary, acting on our instructions: Meta / Instagram (receiving comments and sending messages), Supabase (storage) and Vercel (hosting).
7. Retention
Processing logs are kept for as long as needed for the service to work properly, then deleted — and at any time on request (see section 9).
8. Your rights
Under the GDPR, you have a right of access, rectification, erasure, restriction and objection. To exercise it, write to us at antonin.langlade@gmail.com.
9. Data deletion
To request deletion of the data concerning you (processed comments and the related logs), send an email to antonin.langlade@gmail.com stating your Instagram username. Requests are handled within 30 days.
10. Meta platform compliance
This application uses the Meta API for Instagram and complies with the Meta Platform Terms and the Developer Policies. Use of the information received through the API is limited to the purposes described in this policy.
11. Changes
This policy may be updated; the date of the last update appears at the top of the page.
12. Contact
Antonin Langlade — antonin.langlade@gmail.com